CVE-2020-7957Improper Input Validation in Dovecot

Severity
5.3MEDIUMNVD
EPSS
0.5%
top 32.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateMay 24

Description

The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDdovecot/dovecot2.3.92.3.9.3
Alpinedovecot/dovecot< 2.3.10.1-r0+15

Also affects: Fedora 30, 31

🔴Vulnerability Details

2
GHSA
GHSA-vg8f-j3m8-7g9v: The IMAP and LMTP components in Dovecot 22022-05-24
OSV
CVE-2020-7957: The IMAP and LMTP components in Dovecot 22020-02-12

📋Vendor Advisories

2
Red Hat
dovecot: specially crafted email can cause mailbox to have permanently unaccessible mail2020-02-12
Debian
CVE-2020-7957: dovecot - The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet g...2020

💬Community

1
Bugzilla
CVE-2020-7957 dovecot: specially crafted email can cause mailbox to have permanently unaccessible mail2020-02-07